vciy

CVEs we hold for Mongodb

Records whose assigning authority named Mongodb as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-9754Stack memory disclosure in filemd5 commandMongoDB
CVE-2026-9753Server crash via malformed binary diff passed to $_internalApplyOplogUpdate.MongoDB Server
CVE-2026-9752GeometryCollection with strict-winding polygon causes server crash during 2dsphere index key generationMongoDB Server
CVE-2026-9751Sensitive data could be written to mongod.logMongoDB Server
CVE-2026-9750Metadata name collision on $-prefixed fields causes post-auth server crashMongoDB Server
CVE-2026-9749Using MaxKey() may crash the serverMongoDB Server
CVE-2026-9748$_internalConvertBucketIndexStats may crash the mongod server when working on no timeseries inputMongoDB Server
CVE-2026-9747Crafted cross-shard merge aggregation crashes MongoDB ServerMongoDB Server
CVE-2026-9746Server crashes in case of the use of exchangeMongoDB Server
CVE-2026-9743Aggregation sub-pipeline null dereference may allow DoS via crafted getMoreMongoDB server
CVE-2026-9742Authenticate command with specific mechanism parameter can trigger server crashMongoDB Server
CVE-2026-9741Client side encryption fails to encrypt values in a $vectorSearchMongoDB Server
CVE-2026-9740Unbounded recursion in BSONColumn interleaved-reference causes pre-auth stack overflowMongoDB Server
CVE-2026-9737Find command with $meta sort can lead to crashMongoDB Server
CVE-2026-9735Keyfile contents are in MongoDB Server logsMongoDB Server
CVE-2026-93765Document deletion and process crash via unvalidated method-name dispatch in atomic pop operationMongoDB Inc. Mongoid
CVE-2026-93764Plaintext storage of encrypted fields via skipped embedded models in encryption schema generationMongoDB Inc. Mongoid
CVE-2026-93763Silent plaintext persistence via unresolved callable database name in encryption schema mapMongoDB Inc. Mongoid
CVE-2026-93762Data deletion and attribute disclosure via field-name method injection in in-memory queriesMongoDB Inc. Mongoid
CVE-2026-93761Denial of service via unbounded regex matching in Mongoid's in-memory query matcherMongoDB Inc. Mongoid
CVE-2026-93760NoSQL injection of JavaScript-executing query operators via unsafe-by-default operator guardMongoDB Inc. Mongoid
CVE-2026-93759Server-side JavaScript injection via string query criteria bypassing the strict operator allowlistMongoDB Inc. Mongoid
CVE-2026-93758Cross-principal document update, theft, and deletion via unvalidated id in nested attributesMongoDB Inc. Mongoid
CVE-2026-93395Integer Underflow → Heap Out-of-Bounds Read in `bson_new_from_buffer()MongoDB Inc. C Driver
CVE-2026-93394libmongoc SCRAM client nonce-validation bypassMongoDB Inc. C Driver
CVE-2026-93393Heap overflow via oversized decrypted TLS record sequence in Windows Secure Channel streamMongoDB Inc. C Driver
CVE-2026-92758Logs may collect sensitive informationMongoDB Entity Framework Core Provider
CVE-2026-92757Malformed connection string may disable field level encryptionMongoDB Entity Framework Core Provider
CVE-2026-92756Combining encryption settings may disable encryptionMongoDB Entity Framework Core Provider
CVE-2026-9101Prototype pollution in csv parsingMongoDB, Inc. Compass
CVE-2026-9100Heap memory out of bounds read and crash in C Driver legacy GridFS file readerMongoDB, Inc. C Driver
CVE-2026-89099Race Condition in MongoDB Server Document Value Layer Leads to Memory CorruptionMongoDB Server
CVE-2026-8843Calling createIndex with certain index types can crash mongodMongoDB, Inc. MongoDB Server
CVE-2026-88036GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB C DriverMongoDB C Driver
CVE-2026-88035Heap buffer overflow via wrapped size check during SASL username canonicalization in MongoDB C DriverMongoDB C Driver
CVE-2026-88034GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB C++ DriverMongoDB C++ Driver
CVE-2026-88033GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB Java DriverMongoDB Java Driver
CVE-2026-88032Application denial of service via cancellation race in reactive client-side encryption in MongoDB Java DriverMongoDB org.mongodb:mongodb-driver-reactivestreams Maven…
CVE-2026-88031GridFS data deletion via query-operator injection in file IDs in the MongoDB Go DriverMongoDB Go Driver
CVE-2026-88030GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB Ruby DriverMongoDB Ruby Driver
CVE-2026-88029GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB Python DriverMongoDB Python Driver
CVE-2026-88028Unauthorized document disclosure via query-operator injection in polymorphic relation identifiers in MongoDB…MongoDB (PHP)
CVE-2026-88027Mass deletion and overwrite of embedded documents via query-operator injection in embedded record keys in MongoDB…MongoDB (PHP)
CVE-2026-88026Regular expression injection via unescaped characters in LINQ query translation in MongoDB C# DriverMongoDB C# Driver
CVE-2026-88025GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB C# DriverMongoDB C# Driver
CVE-2026-88024GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB Rust DriverMongoDB Rust Driver
CVE-2026-88023GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB PHP LibraryMongoDB PHP Library
CVE-2026-88022Unauthorized document disclosure and deletion via query-operator injection in explicit equality filters in MongoDB…MongoDB (PHP)
CVE-2026-84971Persistent client crash loop via undersized FLE2 insert-update ciphertext in decryption pathMongoDB libmongocrypt
CVE-2026-84970Heap over-read or silent misparse via 32-bit truncation of JSON length in BSON JSON parserMongoDB C++ Driver
CVE-2026-84969Heap overflow via truncated base64 encoding of binary fields in length-limited JSON outputMongoDB C Driver
CVE-2026-84968Heap out-of-bounds read via corrupt nested BSON in field path error messageMongoDB PHP Driver
CVE-2026-84967Arbitrary command execution via shell-expanded connection string in Launch MongoDB Shell terminalMongoDB for VS Code
CVE-2026-84966BSON element injection via NUL-embedded document keys in builder appendMongoDB C++ Driver
CVE-2026-84965Heap write primitive via size round-up wrap during JSON parsing on 32-bit buildsMongoDB C Driver
CVE-2026-84964Heap corruption via OCSP request double free from crafted multi-URL certificate in TLS clientMongoDB C Driver
CVE-2026-84963Silent field truncation via unchecked int cast of huge JSON string values in JSON-to-BSON parserMongoDB C Driver
CVE-2026-84962Authenticated KMS request forgery via CRLF injection in GCP key identifier stringsMongoDB libmongocrypt
CVE-2026-8431Ops Manager RCE via webhook bodyMongoDB, Inc. Ops Manager
CVE-2026-8336Post-authentication use-after-free error in $_internalJsEmit and mapreduce commandsMongoDB, Inc. MongoDB Server
CVE-2026-82076Integer Overflow in Query Planner Leads to Unbounded Memory Allocation and Denial of Service in MongoDB ServerMongoDB Server
CVE-2026-82075Uncontrolled Resource Consumption in MongoDB Sharded Cluster Router Allows Unauthenticated Denial of ServiceMongoDB Server
CVE-2026-82074Incorrect Authorization in MongoDB Server Aggregation Framework Allows Unauthorized Read Access to Collection DataMongoDB Server
CVE-2026-82073Improper Validation in MongoDB Server Aggregation Framework Allows Authorization Bypass and Unauthorized Collection…MongoDB Server
CVE-2026-82071Insufficient Validation of Storage Engine Configuration Options in MongoDB Server Leads to Out-of-Bounds WriteMongoDB Server
CVE-2026-82070Insufficiently Protected Credentials in MongoDB Server Diagnostic Reporting InterfaceMongoDB Server
CVE-2026-82069Improper Redaction of Query Literals in MongoDB Server Query Statistics Serialization on Sharded Cluster RouterMongoDB Server
CVE-2026-82068Persistent Fatal Assertion Crash in MongoDB Server via Crafted Retryable Write Commands Leads to Denial of ServiceMongoDB Server
CVE-2026-82067Improper Case Sensitivity Handling in MongoDB Server Configuration Validation May Cause Authorization to Remain…MongoDB Server
CVE-2026-82066Heap Out-of-Bounds Read in MongoDB Server Query Planning ComponentMongoDB Server
CVE-2026-82065Insufficient Validation of Storage Configuration Options in MongoDB Server Leads to Persistent Denial of Service via…MongoDB Server
CVE-2026-82064Unauthenticated Denial of Service in MongoDB Server via Assertion Failure in Read Concern Processing on Replica Set…MongoDB Server
CVE-2026-82063Use-After-Free in MongoDB Server Cursor Management Component Leads to Denial of ServiceMongoDB Server
CVE-2026-82062Improper Authorization in MongoDB Server applyOps Command Allows Writes to Arbitrary Internal Storage Tables via…MongoDB Server
CVE-2026-82061Use-After-Free in MongoDB Server Query Execution Memory Tracking Subsystem Leads to Denial of ServiceMongoDB Server
CVE-2026-82060Insufficient Validation of Shard Key Values in MongoDB Server Leads to Query Operator Injection in Change Stream…MongoDB Server
CVE-2026-82059Improper Access Restriction of Internal Aggregation Expression in MongoDB Server Leads to Assertion Failure and Denial…MongoDB Server
CVE-2026-82058Unhandled Exception in MongoDB Server JSON Schema Validation Error Generation Leads to Denial of ServiceMongoDB Server
CVE-2026-82057Type Confusion in MongoDB Server WiredTiger Storage Engine via Custom Collection Configuration Leads to Persistent…MongoDB Server
CVE-2026-82056Race Condition in MongoDB Server Text Index Query Parsing Leads to Heap Use-After-Free and Denial of ServiceMongoDB Server
CVE-2026-82055Null Pointer Dereference in MongoDB Server 2dsphere Index Key Generation Leads to Denial of ServiceMongoDB Server
CVE-2026-82054Uncontrolled Resource Consumption in MongoDB Server JSON Pointer Parser Leads to Denial of ServiceMongoDB Server
CVE-2026-82053Improper Session Handling in MongoDB Server LDAP Authorization Integration Leads to Incorrect Role AssignmentMongoDB Server
CVE-2026-82052$regexFindAll may crash mongod server when byte-matching multi-byte UTF-8 charsMongoDB Server
CVE-2026-8202Post-authentication CPU utilization DoS via $trim/$ltrim/$rtrim operatorsMongoDB, Inc. MongoDB Server
CVE-2026-8201Use-After-Free in MongoDB FLE Query Analysis When Processing Positional Projections on Encrypted FieldsMongoDB, Inc. MongoDB Server
CVE-2026-8200Schema validation log messages may not redact user dataMongoDB, Inc. MongoDB Server
CVE-2026-8199Post-auth memory exhaustion via bitwise match expressionsMongoDB, Inc. MongoDB Server
CVE-2026-81533MongoDB BI Connector ODBC Driver Memory-Safety Issue When Parsing Oversized LIMIT ValuesMongoDB BI Connector ODBC Driver
CVE-2026-81532BI Connector ODBC Driver Improper Bounds Checking on Cursor Name Leading to Memory CorruptionMongoDB BI Connector ODBC Driver
CVE-2026-81530KMS master key exposure via unredacted credential serialization in driver settings stringMongoDB C# Driver
CVE-2026-81529Connection-option injection via unescaped settings in the canonical MongoDB URL builderMongoDB C# Driver
CVE-2026-81528NoSQL injection via array replacement bypassing update shape validation in driver write pathMongoDB C# Driver
CVE-2026-81527NoSQL injection via unquoted constant GroupBy keys in LINQ pipeline translationMongoDB C# Driver
CVE-2026-81526Cross-database write redirection via unvalidated dotted database name in bulk write namespacesMongoDB Rust Driver
CVE-2026-81525Cross-tenant database retargeting via dot/NUL injection in namespace strings in the PHP DriverMongoDB PHP Extension
CVE-2026-81524Cross-tenant database retargeting via dot/NUL injection in namespace strings in the C DriverMongoDB C Driver
CVE-2026-81523Cross-tenant database retargeting via dot/NUL injection in namespace strings in libmongocryptMongoDB libmongocrypt
CVE-2026-81522Cross-tenant database retargeting via dot/NUL injection in namespace strings in the C++ DriverMongoDB C++ Driver
CVE-2026-81521Cross-database write retargeting via unvalidated dotted database name in Client.BulkWrite in the MongoDB Go DriverMongoDB GO Driver
CVE-2026-81520MongoDB Connector for BI Unbounded Authentication Negotiation Leading to Connection ExhaustionMongoDB BI Connector
CVE-2026-81518BI Connector Optional Client Certificate Verification Allows Unauthenticated ConnectionsMongoDB BI Connector
CVE-2026-81517MongoDB Connector for BI Improper Error Handling of Log Write Failures May Cause Loss of SQL ServiceMongoDB BI Connector
CVE-2026-81490MongoDB Connector for BI Improper Error Handling During Schema Sampling May Cause Loss of SQL ServiceMongoDB BI Connector
CVE-2026-8063Post-auth null pointer dereference when aggregating against a view with empty search pipelineMongoDB Server
CVE-2026-8053FlatBSON Duplicate Field Index DriftMongoDB, Inc. MongoDB Server
CVE-2026-77586MongoDB Connector for BI Unescaped Object Names in Generated SHOW CREATE OutputMongoDB BI Connector
CVE-2026-77184MongoDB Connector for BI Incomplete Escaping of Stored Metadata in Generated SHOW CREATE OutputMongoDB BI Connector
CVE-2026-76798MongoSQL Transition Readiness Tool Improper Output Encoding in Generated HTML ReportsMongoDB BI Connector Transition Readiness Report
CVE-2026-76797MongoSQL Transition Readiness Tool Improper Neutralization of Formula Elements in Generated ReportsMongoDB BI Connector Transition Readiness Report
CVE-2026-76794MongoDB BI Connector Transition Readiness Report Improper HTML Encoding When Processing Database MetadataMongoDB BI Connector Transition Readiness Report
CVE-2026-75573MongoDB Connector for BI mongodrdl Logs TLS Private-Key Password When Duplicate Options Are SuppliedMongoDB BI Connector
CVE-2026-75159MongoDB BI Connector Improper Memory Handling During Failed Kerberos Authentication May Cause Process TerminationMongoDB BI Connector
CVE-2026-6915Flaw in the updateUser Command May Allow Unauthorized Configuration ChangeMongoDB Server
CVE-2026-6914MD5 checksum creation may cause availability lossMongoDB Server
CVE-2026-6811PHP Stack ExhaustionMongoDB Inc. PHP Driver
CVE-2026-6691MongoDB C Driver Cyrus SASL Canonicalization Buffer OverflowMongoDB C Driver
CVE-2026-6231bson_validate may skip validation when processing certain inputsMongoDB Inc. C Driver
CVE-2026-5170Users could trigger a crash of mongod primaries during promotion to shardedMongoDB Server
CVE-2026-4359Heap-buffer-over-read in _mongoc_http_send via strstr on non-null-terminated bufferMongoDB C Driver
CVE-2026-4358Memory safety issues in slot-based execution hash table spillMongoDB Server
CVE-2026-4148ExpressionContext use-after-free in classic engine $lookup and $graphLookup aggregation operatorsMongoDB Server
CVE-2026-4147Stack memory disclosure in filemd5 commandMongoDB Server
CVE-2026-25613An unsafe cast in the MongoDB query planner can result in a segmentation fault.MongoDB Server
CVE-2026-25612Internal ResourceId collision may affect unrelated collectionsMongoDB Server
CVE-2026-25611Pre-Authentication Memory Exhaustion Denial of Service in MongoDB ServerMongoDB Server
CVE-2026-25610Invalid $geoNear index hint may cause server crashMongoDB Server
CVE-2026-25609profile command may permit unauthorized configurationMongoDB Server
CVE-2026-2303Heap Out-of-Bounds Read in Go Driver GSSAPI C Wrappers enables application crash or information leakMongoDB Go Driver
CVE-2026-2302Unsafe Reflection in Mongoid::Criteria.from_hashMongoDB Ruby Driver
CVE-2026-19503Insufficient OIDC endpoint validation could invoke unintended local protocol handlersMongoDB Schema Builder CLI
CVE-2026-19502Insufficient redaction of sensitive configuration values in diagnostic output of MongoDB SQL Schema Builder CLIMongoDB Schema Builder CLI
CVE-2026-19004MongoDB BI Connector ODBC Driver Memory-Safety Issue When Handling Stored Procedure Output ParametersMongoDB BI Connector ODBC Driver
CVE-2026-19003MongoDB BI Connector ODBC driver may write outside an allocated buffer when the setup dialog opens a data source with…MongoDB BI Connector ODBC Driver
CVE-2026-19002Crafted database metadata may cause memory corruption in MongoDB BI Connector ODBC DriverMongoDB BI Connector ODBC Driver
CVE-2026-19001MongoDB BI Connector ODBC driver may write outside an allocated buffer when handling oversized catalog object namesMongoDB BI Connector ODBC Driver
CVE-2026-18888MongoDB BI Connector ODBC driver may write outside an allocated buffer when retrieving large floating point values as…MongoDB BI Connector ODBC Driver
CVE-2026-18712Improper Authorization in MongoDB Queryable Encryption Maintenance Operations Allows Unauthorized Modification of Other…MongoDB Server
CVE-2026-18711Use-After-Free in MongoDB Query Execution Engine Leads to Denial of Service and Potential Memory DisclosureMongoDB Server
CVE-2026-18710Cleartext Storage of Sensitive Information in MongoDB Driver Logging During Client InitializationMongoDB Driver
CVE-2026-18709Missing Authorization in MongoDB Sharded Transaction Commit/Abort Handling Leads to Cross-Shard Data InconsistencyMongoDB Server
CVE-2026-18708Improper Neutralization of Input in MongoDB Server's JavaScript Scripting Engine Leads to Unauthorized Code Execution…MongoDB Server
CVE-2026-18707Improper Input Validation in MongoDB Aggregation Command Handling Leads to Denial of ServiceMongoDB Server
CVE-2026-18706Use-After-Free in MongoDB $graphLookup Aggregation Stage Leads to Denial of Service and Potential Remote Code ExecutionMongoDB Server
CVE-2026-18705Improper Authorization in MongoDB Atlas Vector Search Allows Unauthorized Access to Protected View DataMongoDB Server
CVE-2026-18704Improper Authorization in MongoDB Aggregation Framework Allows Read-Only User to Perform Unauthorized Write OperationsMongoDB Server
CVE-2026-18703Improper Enforcement of Authentication Mechanism Restrictions in MongoDB Server Allows Use of Disabled Authentication…MongoDB Server
CVE-2026-18702Improper Authorization in MongoDB profile Command Allows Unauthorized Modification of Server-Wide Diagnostic SettingsMongoDB Server
CVE-2026-18701Type Confusion in MongoDB Query Subsystem Leads to Denial of ServiceMongoDB Server
CVE-2026-18700Use-After-Free in MongoDB Geospatial Validation Leads to Denial of ServiceMongoDB Server
CVE-2026-18699Improper Input Validation in MongoDB Query Planner Leads to Denial of ServiceMongoDB Server
CVE-2026-18698Improper Authorization in MongoDB Server Allows Unauthorized Actions on System Collections via the validate CommandMongoDB Server
CVE-2026-18697Improper Input Validation in MongoDB Aggregation Framework Allows Unauthenticated Denial of Service on mongosMongoDB Server
CVE-2026-18696Improper Authorization in MongoDB applyOps Command Handling Allows Unauthorized DDL Operations on CollectionsMongoDB Server
CVE-2026-18695Improper Input Validation in MongoDB Timeseries Query Processing Leads to Denial of ServiceMongoDB Server
CVE-2026-18694Out-of-Bounds Read in MongoDB Geospatial Query Processing Leads to Denial of Service and Potential Memory DisclosureMongoDB Server
CVE-2026-18693Out-of-Bounds Read/Write in MongoDB Timeseries Bucket Handling Leads to Denial of Service and Potential Memory…MongoDB Server
CVE-2026-18692Use-After-Free in MongoDB Timeseries Bucket Handling Leads to Denial of Service and Potential Remote Code ExecutionMongoDB Server
CVE-2026-18691Improper Authentication in MongoDB Intra-Cluster Connections Allows Credential ExposureMongoDB Server
CVE-2026-18690Improper Authorization in MongoDB Server Allows Unauthorized Actions on System CollectionsMongoDB Server
CVE-2026-18688Out-of-Bounds Read in MongoDB Aggregation Framework Leads to Denial of Service and Potential Memory DisclosureMongoDB Server
CVE-2026-18687Improper Validation in MongoDB Queryable Encryption Maintenance Operation Leads to Denial of Service and Index…MongoDB Server
CVE-2026-1850An authorized user may disable the MongoDB server by issuing a certain type of complex query due to boolean expression…MongoDB Server
CVE-2026-1849Mongod can run out of stack memory when expressions create deeply nested documentsMongoDB Server
CVE-2026-1848Connections received from the proxy port may not count towards total accepted connectionsMongoDB Server
CVE-2026-1847MongoDB Server may crash when inserting large documentsMongoDB Server
CVE-2026-14881Compass connection import allows to override OIDC browser open command (usually set through settings), allowing for…MongoDB Compass
CVE-2026-13078Local File Disclosure in MongoDB Server via MozJS Scripting Engine Module LoaderMongoDB Server
CVE-2026-13077Out-of-Bounds Heap Read in BSON CodeWScope Element Parsing via Malformed BSONColumn DataMongoDB Server
CVE-2026-13076Aggregation Framework Memory Exhaustion Leading to Process TerminationMongoDB Server
CVE-2026-13075$rankFusion and $scoreFusion Unbounded Memory Allocation During Error Suggestion GenerationMongoDB Server
CVE-2026-13074Awaitable Hello Command in Exhaust Mode Unthrottled Response Loop Leading to Denial of ServiceMongoDB Server
CVE-2026-13073MongoDB Aggregation Command Invariant Assertion Failure Leading to Process TerminationMongoDB Server
CVE-2026-13072MongoDB Improper Input Validation in Compute Mode External Data Processing Leading to Memory CorruptionMongoDB Server
CVE-2026-13071Server-Side JavaScript Aggregation Expression Memory Safety Issue Leading to Process TerminationMongoDB Server
CVE-2026-13070Improper Validation of OCSP Response During Outbound TLS Handshake Leading to Process TerminationMongoDB Server
CVE-2026-13069Queryable Encryption FLE2 Find Payload Missing Input Validation Leading to Resource ExhaustionMongoDB Server
CVE-2026-13068MongoDB mongos Improper Authorization Check in Cursor Termination Allowing Cross-Database Privilege MisuseMongoDB Server
CVE-2026-13067tlsCATrusts Role Restriction Not Enforced via PROXY Protocol v2 on Unix Domain SocketMongoDB Server
CVE-2026-13066Server-Side JavaScript DBPointer BSON Serialization Memory DisclosureMongoDB Server
CVE-2026-13065MongoDB $linearFill Window Function Improper Input Validation Leading to Process TerminationMongoDB Server
CVE-2026-13064MongoDB $jsonSchema Query Operator Excessive CPU Consumption Leading to Denial of ServiceMongoDB Server
CVE-2026-13063libmongocrypt Improper Input Validation Leading to Process TerminationMongoDB Server
CVE-2026-13062MongoDB mongos Improper Validation of Internal Flags in Queryable Encryption Write Commands on Sharded ClustersMongoDB Server
CVE-2026-13061Improper Access Control Allowing Cross-User Session Metadata Disclosure in $listSessions Aggregation StageMongoDB Server
CVE-2026-13060$graphLookup Aggregation Stage Authorization Check Inconsistency Allowing Unauthorized Collection AccessMongoDB Server
CVE-2026-13059Improper Validation of Client-Supplied Command Parameters Allowing Role-Based Access Control BypassMongoDB Server
CVE-2026-13058Transaction Command Insufficient Input Validation Leading to Process TerminationMongoDB Server
CVE-2026-13057Authorization Bypass via Client-Supplied $search.mergingPipeline Leaks Unauthorized Collection Data Through…MongoDB Server
CVE-2026-13056A user with read access can cause a DoS by executing a specifically crafted query to consume a large amount of RAMMongoDB Server
CVE-2026-13055Server crash via aggregation pipeline expression with compound wildcard index specificationMongoDB Server
CVE-2026-11933Post-authentication use-after-free in server-side JavaScript BSON-to-array conversionMongoDB
CVE-2025-7259Certain Queries with Duplicate _id Fields May Cause MongoDB Server to CrashMongoDB Server
CVE-2025-6714Incorrect Handling of incomplete data may prevent mongoS from Accepting New ConnectionsMongoDB Server
CVE-2025-6713MongoDB Server may be susceptible to privilege escalation due to $mergeCursors stageMongoDB Server
CVE-2025-6712MongoDB Server may be susceptible to DoS due to Accumulated Memory AllocationMongoDB Server
CVE-2025-6711Incomplete Redaction of Sensitive Information in MongoDB Server LogsMongoDB Server
CVE-2025-6710Pre-authentication Denial of Service Stack Overflow Vulnerability in JSON Parsing via Excessive Recursion in MongoDBMongoDB Server
CVE-2025-6709Pre-Authentication Denial of Service Vulnerability in MongoDB Server's OIDC AuthenticationMongoDB Server
CVE-2025-6707Race condition in privilege cache invalidation cycleMongoDB Server

200 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.